CVE-2017-7755

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
11/06/2018
Last modified:
25/11/2025

Description

The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 52.2.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 54.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 52.2.0 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*